ThinkPatternGet the app
Story
TECHNOLOGY · SEP 28, 2026

Citrix Patches Critical NetScaler Zero-Days Under Active Global Attack

Citrix released emergency updates for NetScaler devices after two critical remote code execution vulnerabilities were exploited by hackers globally.

Cloud Software Group, the parent company of Citrix, released emergency security updates on September 27 and 28, 2026, to address eight vulnerabilities in its NetScaler Application Deliver Controller (ADC) and NetScaler Gateway devices. The most severe flaws, CVE-2026-88771 and CVE-2026-88772, both carry severity scores of 9.5/10 and allow unauthenticated remote attackers to execute arbitrary commands or cause a denial of service. Citrix confirmed that these zero-days were under active attack before fixes were available.

The vulnerabilities were first flagged by researchers at watchTowr, who discovered the exploits during forensic investigations. Security experts warned that the flaws could allow attackers to install backdoors, harvest VPN credentials, or pivot into internal networks. In response, the United States Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerabilities to its Known Exploited Vulnerabilities catalogue, mandating a patching deadline of September 30 for federal agencies.

International agencies including the Australian Signals Directorate and the Dutch National Cyber Security Center urged immediate updates and log reviews. While the Australian Cyber Security Centre issued a critical alert, it reported that it had not yet received reports of confirmed exploitation within Australia as of Monday. CISA advised organizations to capture forensic data before applying patches to ensure evidence of potential intrusions was not erased.


Reported across 9 outlets
Actors
Citrix SystemsCybersecurity and Infrastructure Security Agency

Keep reading in the app

The full story and every source, free in the app.